CVE-2023-28120
published 2025-01-09CVE-2023-28120: There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.
PriorityP425medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.92%
56.7th percentile
There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rails | < rails 2:6.1.7.3+dfsg-1 (bookworm) | rails 2:6.1.7.3+dfsg-1 (bookworm) |
| rails | activesupport | >= 0 < 6.1.7.3 | 6.1.7.3 |
| rails | activesupport | >= 6.1.7.3 < 6.1.7.3 | 6.1.7.3 |
| rails | activesupport | >= 7.0.0 < 7.0.4.3 | 7.0.4.3 |
| rails | activesupport | >= 7.0.4.3 < 7.0.4.3 | 7.0.4.3 |
| rubyonrails | rails | >= 0 < 2:6.0.3.7+dfsg-2+deb11u2 | 2:6.0.3.7+dfsg-2+deb11u2 |
| rubyonrails | rails | >= 0 < 2:6.1.7.3+dfsg-1 | 2:6.1.7.3+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:6.1.7.3+dfsg-1 | 2:6.1.7.3+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:6.1.7.3+dfsg-1 | 2:6.1.7.3+dfsg-1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
ghsa5.3MEDIUM
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-28120: There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input
osv·2025-01-09·CVSS 5.3
CVE-2023-28120 [MEDIUM] CVE-2023-28120: There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input
There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.
OSV
Possible XSS Security Vulnerability in SafeBuffer#bytesplice
osv·2023-03-15·CVSS 5.3
CVE-2023-28120 [MEDIUM] Possible XSS Security Vulnerability in SafeBuffer#bytesplice
Possible XSS Security Vulnerability in SafeBuffer#bytesplice
There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.
This vulnerability has been assigned the CVE identifier CVE-2023-28120.
Versions Affected: All. Not affected: None Fixed Versions: 7.0.4.3, 6.1.7.3
# Impact
ActiveSupport uses the SafeBuffer string subclass to tag strings as html_safe after they have been sanitized.
When these strings are mutated, the tag is should be removed to mark them as no longer being html_safe.
Ruby 3.2 introduced a new bytesplice method which ActiveSupport did not yet understand to be a mutation.
Users on older versions of Ruby are likely unaffected.
All users running an affected release and using bytesplice should either upgra
GHSA
Possible XSS Security Vulnerability in SafeBuffer#bytesplice
ghsa·2023-03-15·CVSS 5.3
CVE-2023-28120 [MEDIUM] CWE-79 Possible XSS Security Vulnerability in SafeBuffer#bytesplice
Possible XSS Security Vulnerability in SafeBuffer#bytesplice
There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.
This vulnerability has been assigned the CVE identifier CVE-2023-28120.
Versions Affected: All. Not affected: None Fixed Versions: 7.0.4.3, 6.1.7.3
# Impact
ActiveSupport uses the SafeBuffer string subclass to tag strings as html_safe after they have been sanitized.
When these strings are mutated, the tag is should be removed to mark them as no longer being html_safe.
Ruby 3.2 introduced a new bytesplice method which ActiveSupport did not yet understand to be a mutation.
Users on older versions of Ruby are likely unaffected.
All users running an affected release and using bytesplice should either upgra
Red Hat
rubygem-activesupport: Possible XSS in SafeBuffer#bytesplice
vendor_redhat·2023-03-15·CVSS 5.3
CVE-2023-28120 [MEDIUM] CWE-79 rubygem-activesupport: Possible XSS in SafeBuffer#bytesplice
rubygem-activesupport: Possible XSS in SafeBuffer#bytesplice
There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.
A Cross-Site-Scripting vulnerability was found in rubygem ActiveSupport. If the new bytesplice method is called on a SafeBuffer with untrusted user input, malicious code could be executed.
Mitigation: Avoid calling bytesplice on a SafeBuffer (html_safe) string with untrusted user input.
Package: 3scale-amp-backend-container (Red Hat 3scale API Management Platform 2) - Affected
Package: 3scale-amp-zync-container (Red Hat 3scale API Management Platform 2) - Will not fix
Package: 3scale-toolbox-container (Red Hat 3scale API Management Platform 2) - Will not fix
Package: rubygem-activesupport (Red Hat Ope
Debian
CVE-2023-28120: rails - There is a vulnerability in ActiveSupport if the new bytesplice method is called...
vendor_debian·2023·CVSS 5.3
CVE-2023-28120 [MEDIUM] CVE-2023-28120: rails - There is a vulnerability in ActiveSupport if the new bytesplice method is called...
There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.
Scope: local
bookworm: resolved (fixed in 2:6.1.7.3+dfsg-1)
bullseye: resolved (fixed in 2:6.0.3.7+dfsg-2+deb11u2)
forky: resolved (fixed in 2:6.1.7.3+dfsg-1)
sid: resolved (fixed in 2:6.1.7.3+dfsg-1)
trixie: resolved (fixed in 2:6.1.7.3+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://discuss.rubyonrails.org/t/cve-2023-28120-possible-xss-security-vulnerability-in-safebuffer-bytesplice/82469https://github.com/rails/rails/commit/3cf23c3f891e2e81c977ea4ab83b62bc2a444b70https://lists.fedoraproject.org/archives/list/[email protected]/message/UPV6PVCX4VDJHLFFT42EXBBSGAWZICOW/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZE5W4MH6IE4DV7GELDK6ISCSTFLHKSYO/https://security.netapp.com/advisory/ntap-20240202-0006/https://www.debian.org/security/2023/dsa-5389
2025-01-09
Published